Title: MCPDO — AI Operations
Author: TopHive
Published: <strong>October 7, 2026</strong>
Last modified: October 7, 2026

---

Search plugins

![](https://ps.w.org/mcpdo/assets/banner-772x250.png?rev=3733389)

![](https://ps.w.org/mcpdo/assets/icon-256x256.png?rev=3733389)

# MCPDO — AI Operations

 By [TopHive](https://profiles.wordpress.org/tophive/)

[Download](https://downloads.wordpress.org/plugin/mcpdo.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/mcpdo/#description)
 * [Reviews](https://wordpress.org/plugins/mcpdo/#reviews)
 *  [Installation](https://wordpress.org/plugins/mcpdo/#installation)
 * [Development](https://wordpress.org/plugins/mcpdo/#developers)

 [Support](https://wordpress.org/support/plugin/mcpdo/)

## Description

MCPDO finds bounded WooCommerce operational issues, preserves the evidence behind
each finding, and lets supported AI clients prepare exact product fixes without 
bypassing WordPress permissions or human approval.

Free V1 focuses on one complete outcome loop: **find it  prove it  preview a fix
approve  apply  verify  recover when safe.**

 * Run a read-only Store Health Audit.
 * Review deterministic findings with evidence, method, limitations, and evidence
   quality.
 * Preview exact reversible product changes before anything is written.
 * Update supported product name, short/full description, publication status, categories,
   tags, existing-media featured image, and inventory fields.
 * Require explicit approval before every supported write.
 * Verify the observed result independently after the write.
 * Recover only the captured MCPDO fields when recovery is still safe and no newer
   merchant edit would be overwritten.
 * Restrict every connection with granular scopes and per-tool switches.
 * Review an immutable operational activity timeline.

MCPDO does not claim conversion or revenue causality from the V1 audit signals. 
Product content, inventory, pending/failed order status, coupons, and supported 
WooCommerce configuration values are reported as observations only.

WooCommerce is not required to activate MCPDO. When WooCommerce is unavailable or
below the supported commerce boundary, MCPDO remains active and reports commerce
features as unavailable.

#### Safety by default

 * Global writes are off by default.
 * Free V1 writes are limited to the explicit reversible WooCommerce product-field
   allowlist; arbitrary WordPress, PHP, SQL, shell, filesystem, order, customer,
   or financial mutation is not exposed.
 * Preview, permission checks, approval, verification, and recovery rules remain
   server-authoritative.
 * No raw PHP, SQL, shell, filesystem, bulk financial mutation, or automatic customer
   messaging ability is exposed.
 * Evidence and activity metadata are sanitized before persistence.

#### MCP connectivity

MCPDO includes a bounded native MCP endpoint and registers WordPress Abilities for
supported operations. Supported clients authenticate with MCPDO OAuth 2.1 Authorization
Code + PKCE. OAuth bearer tokens are accepted only by the dedicated MCPDO endpoint
and do not create a WordPress login session or authenticate general WordPress REST
API routes. MCPDO persists only one-way token hashes needed to validate and rotate
grants.

### Development source

The human-readable admin source used to build the distributed JavaScript and CSS
is included in the plugin under `assets/src/`. The deployed package also includes`
package.json`, `pnpm-lock.yaml`, and `tsconfig.admin.json`; see `source.txt` for
the pinned toolchain and rebuild command.

### Privacy

MCPDO stores operational audit, finding, evidence, operation, recovery, task, and
activity records in the site’s WordPress database.

 * No mandatory telemetry is sent to TopHive.
 * MCPDO does not store plaintext OAuth bearer/refresh tokens and does not create
   WordPress Application Passwords for external MCP clients.
 * Supported PII and secret-shaped values are redacted before evidence persistence.
 * WordPress privacy export and erasure tools can export or unlink user references
   from MCPDO operational history.
 * Default retention is 90 days for activity, 30 days for evidence, 30 days for 
   completed task details, and 14 days for recoverable ChangeSets.
 * Administrators can change supported retention windows in MCPDO settings.
 * MCPDO never removes WooCommerce store data during uninstall.

### External services

MCPDO core does not require an MCPDO Cloud account, does not use a TopHive remote
administration control plane, and does not proxy site data through TopHive servers
by default. The OAuth authorization/token endpoints and native MCP endpoint are 
hosted by the merchant’s own WordPress site.

An external AI/MCP client is optional and is selected/configured by the site administrator.
MCPDO does not initiate outbound requests to those AI providers in Core V1; the 
configured client connects to the site’s MCP endpoint. Data the administrator chooses
to expose through that client is governed by the administrator’s client choice and
that client’s own terms and privacy policy.

## Installation

 1. Install and activate MCPDO.
 2. Open **MCPDO > Overview** and choose **Scan my store**.
 3. Run the read-only Store Health Audit and review the evidence-backed findings.
 4. When you want AI-assisted inspection or a supported fix, open **MCPDO > Connections**
    and choose your MCP client.
 5. Complete OAuth consent, then connect the client to the MCP endpoint shown by MCPDO.
 6. Review the write-safety defaults before enabling supported writes.
 7. Preview the exact change, approve it explicitly, then let MCPDO apply and verify
    the observed result.

An AI client is not required to run the audit. WooCommerce commerce features require
WooCommerce 10.8 or newer.

## FAQ

### Do I need ChatGPT, Claude, Cursor, or another AI client to use MCPDO?

No. You can install MCPDO and run the read-only Store Health Audit without connecting
an AI client. Connect a supported MCP client only when you want AI-assisted evidence
inspection or supported change previews.

### Does MCPDO send my store data to TopHive?

No. Core V1 is self-hosted-first and has no mandatory TopHive telemetry or cloud
proxy. If you connect an external AI client, that client communicates with your 
WordPress site according to the credentials and network path you configure.

### Does MCPDO store my AI client’s credential?

For MCP OAuth, access and refresh token material is stored only as one-way hashes
required to validate/rotate grants; plaintext bearer/refresh tokens are not persisted
by MCPDO. MCPDO does not create WordPress Application Passwords for external MCP
clients.

### Does MCPDO make autonomous changes?

No. Supported Free V1 writes require an exact preview and explicit approval from
an authenticated WordPress administrator through MCPDO’s local WordPress REST/admin
flow. The MCPDO OAuth bearer cannot authenticate that approval route. Connection
scope, WordPress capability, tool policy, global safety, fresh-target, verification,
and recovery guards remain server-authoritative.

### What can MCPDO change in Free V1?

MCPDO can change only the explicit reversible WooCommerce product allowlist: name,
short description, full description, publication status, category IDs, tag IDs, 
an existing WordPress media attachment as featured image, manage-stock state, stock
quantity, and stock status. It cannot perform arbitrary database, filesystem, PHP,
shell, order, customer, coupon, or financial mutations.

### Is WooCommerce required?

No. MCPDO can activate without WooCommerce. WooCommerce audit and commerce operations
become available when a supported WooCommerce version is active.

### What happens when I delete MCPDO?

Deactivation never deletes durable MCPDO data. On uninstall, MCPDO keeps its data
by default unless an administrator explicitly enables **Remove MCPDO data when the
plugin is deleted** first. MCPDO never deletes WooCommerce store data.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“MCPDO — AI Operations” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ TopHive ](https://profiles.wordpress.org/tophive/)

[Translate “MCPDO — AI Operations” into your language.](https://translate.wordpress.org/projects/wp-plugins/mcpdo)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/mcpdo/), check out 
the [SVN repository](https://plugins.svn.wordpress.org/mcpdo/), or subscribe to 
the [development log](https://plugins.trac.wordpress.org/log/mcpdo/) by [RSS](https://plugins.trac.wordpress.org/log/mcpdo/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Added the installable Free V1 foundation, native MCP transport, and WordPress
   Abilities.
 * Added WooCommerce read abilities and the Store Health Audit.
 * Added evidence-backed findings with sanitized provenance and bounded retention.
 * Added bounded multi-field WooCommerce product content, status, taxonomy, featured-
   image, and inventory operations with plan/preview/approval/apply/verify/recover
   flow.
 * Added OAuth 2.1 + PKCE client setup, granular connection scopes, per-tool policy
   switches, rate/concurrency guards, and redacted MCP tool activity.
 * Added Activity history, privacy controls, retention settings, and WordPress privacy
   integration.
 * Added accessibility, RTL, internationalization, release, and WordPress.org hardening
   gates.

## Meta

 *  Version **1.0.0**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.9 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [AI](https://wordpress.org/plugins/tags/ai/)[mcp](https://wordpress.org/plugins/tags/mcp/)
   [operations](https://wordpress.org/plugins/tags/operations/)[store health](https://wordpress.org/plugins/tags/store-health/)
   [woocommerce](https://wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://wordpress.org/plugins/mcpdo/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/mcpdo/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/mcpdo/reviews/)

## Contributors

 *   [ TopHive ](https://profiles.wordpress.org/tophive/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/mcpdo/)